
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Amazon attributed debug and chalk npm hijack to North Korea’s Sapphire Sleet, elevating a supply chain attack previously seen as

Amazon attributed debug and chalk npm hijack to North Korea’s Sapphire Sleet, elevating a supply chain attack previously seen as

CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical

The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.

Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in

Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.

Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud

Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.

A new postmortem reveals OpenAI’s rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face

Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in

Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.